Phone number leak: why it is the key to your entire digital life
In Russia, a mobile phone number is the de facto universal login: signing in to Gosuslugi (Госуслуги), banking apps, Telegram, and marketplaces. By default, an SMS code is the main confirmation factor. This means that a person who controls your number controls a significant part of your digital services.
A leaked phone number by itself makes you a target for targeted phishing and spam. Much more serious is SIM swap: a situation where a fraudster obtains a duplicate of your SIM card through the operator, after which SMS codes from banks and services start going to them. This scenario is technically possible with all Russian operators and has been consistently seen in practice in 2024–2025.
Below is how SIM swap works exactly, which services are hit first, how to protect yourself (a PIN in the operator account, two-factor authentication not via SMS, a separate service number), and what to do if your Telegram account is hijacked.
In short
- A phone number is the main login factor for all key Russian services.
- SIM swap = issuing a duplicate of your SIM, after which SMS codes go to someone else.
- Protection #1 is a PIN for SIM replacement in your operator account.
- Protection #2 is two-factor authentication through an app (TOTP), not through SMS.
- A Telegram account is protected by a “cloud password” (Settings → Privacy → Two-Step Verification).
- A useful practice is a separate number for financial services, not published anywhere.
What SIM swap is and how it works
SIM swap is the SIM replacement procedure that a mobile operator performs at the request of the number owner. The standard scenario: a user has lost or damaged a SIM, comes to the operator’s office with a passport, and receives a new SIM with the same number. The old SIM stops working at that moment.
The fraudster scenario
An attacker comes to the operator’s office with a fake power of attorney or the victim’s passport and requests a duplicate SIM. From that moment, all SMS and calls go to the new SIM, and standard confirmations of the “a code will arrive by SMS” type work in the fraudster’s favor. The victim notices the problem when the mobile network stops working for them.
What is hit first
First, banking apps, because signing in to them uses an SMS code. Then Gosuslugi (sign-in through SMS confirmation), Telegram (sign-in by SMS code without a cloud password), marketplaces, and delivery services. Gosuslugi is especially critical because it provides access to tax services, the summons registry, and extracts from state registries.
Telegram account hijacking
After gaining control of the number, the fraudster requests a Telegram login, receives the SMS code, and signs in. If the victim has not enabled two-factor authentication (Settings → Privacy → Two-Step Verification), access to the account is transferred instantly. After that comes phishing sent to contacts, removal from your chats, and sometimes attempts at blackmail based on the contents of messages.
Why SMS is a weak factor
The SMS channel is more than 30 years old; it was not designed to protect against interception and spoofing. Today, SMS remains an authentication factor in most services because it is familiar and widely available, but technically it is the weak link: a SIM can be reissued, SMS can be intercepted at the SS7 signaling level, and SMS can be redirected through forwarding.
What this means in practice
| What you notice | What it may mean | What to do |
|---|---|---|
| The network suddenly disappeared on your phone | Possible SIM swap | Go urgently to the operator’s office with your passport |
| An expected SMS code from the bank did not arrive | SMS is going to another SIM | Block the SIM, block the card through the app |
| Incoming call: “bank, suspicious transaction” | Targeted phishing using a leaked number | Hang up, call the bank back using the number on the card |
| SMS: “Telegram login attempt” | Someone knows your number and is trying to sign in | Enable a cloud password (Two-Step Verification) |
| Spam mentioning your full name and city | The database is linked to your personal data | Ignore it, do not reply, do not follow links |
| Contacts receive strange messages from you | Your Telegram account has been hijacked | Recover it through the cloud password or e-mail |
How to check right now
A basic four-step sequence. First, set a PIN for SIM replacement in your operator account (Beeline, MTS, MegaFon, Tele2, Yota). This option has different names, but every operator has it. Second, enable a cloud password in Telegram (Settings → Privacy and Security → Two-Step Verification). Third, in banking apps, switch from SMS confirmation to push notifications or biometrics. Fourth, for critical services (Gosuslugi, your main bank), enable two-factor authentication through an authenticator app where it is supported.
At the same time, check whether your full name appears in public repressive registries. Wanted Radar shows data from the Russian Ministry of Internal Affairs wanted list.
Check your full name in the Ministry of Internal Affairs wanted list
Warning signs vs false alarm
A real SIM swap signal is the sudden disappearance of the mobile network on a working phone in a coverage area. If the network disappears and does not come back after rebooting and moving the SIM to another slot, go immediately to the operator’s office with your passport to block it. At the same time, block your cards through the bank app (over the internet, not by SMS).
Spam calls and SMS mentioning your full name are not SIM swap; they are simply a leaked number. The danger level is lower, and the response is different: do not answer, do not press “1 to connect to an operator,” and do not follow links. A database with your number and full name is already in the hands of fraudsters; it cannot be recalled, you can only avoid reacting.
What to do next
- Set a PIN for SIM replacement in your mobile operator account.
- Enable a cloud password in Telegram (Two-Step Verification).
- Replace SMS confirmation with push or an authenticator app where possible.
- Get a separate number for financial services and Gosuslugi, and do not list it on social networks or public profiles.
- Subscribe to notifications about all bank operations, not only large ones.
- If the network disappears for no visible reason, go immediately to the operator’s office with your passport.
- Study current leak statistics at TASS and an international analysis of the “probiv” (пробив) industry in The Guardian.
Disclaimer: this material is for informational purposes and is not legal advice. For a specific situation, contact a lawyer or an information security specialist. Information in registries is updated retroactively and may differ from the current situation.
Conclusion
In modern Russian digital infrastructure, a phone number is the key to a large part of your data and accounts. A leaked number by itself creates a level of risk that can be reduced with basic hygiene: a PIN for SIM replacement, a Telegram cloud password, and switching from SMS to an authenticator app. These actions take one evening once and remove the most common attack vector.
Wanted Radar helps close a related question: whether you appear in open state wanted registries and repressive lists. This is a separate layer of risk, unrelated to financial leaks, but it is useful to check it regularly.